subagents-and-teams

Warn

Audited by Snyk on Mar 8, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.80). The guide explicitly documents a 'bypassPermissions' mode and shows subagents with terminal/Bash tool access and delegation patterns that would allow an agent to skip permission checks and run arbitrary commands that can modify the host system.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 8, 2026, 03:10 PM